From: "Zhang, Yidong (David)" <yidong.zhang@amd.com>
To: Lizhi Hou <lizhi.hou@amd.com>,
quic_jhugo@quicinc.com, karol.wachowski@linux.intel.com,
max.zhen@amd.com, ogabbay@kernel.org,
dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org
Cc: sonal.santan@amd.com, mario.limonciello@amd.com
Subject: Re: [PATCH V0 14/21] accel/amdxdna: Fix fence timeline name and context allocation
Date: Tue, 29 Sep 2026 17:20:37 -0700 [thread overview]
Message-ID: <906d1899-26af-4829-8a4b-9d451ff13917@amd.com> (raw)
In-Reply-To: <c5da23b0-1552-b601-78e9-602e4140297d@amd.com>
On 9/28/2026 2:06 PM, Lizhi Hou wrote:
>
> On 9/25/26 18:34, David Zhang wrote:
>> This is part of the fix to align BO reservation locking and fence
>> management with aie2.
>>
>> Fences published into BO reservation objects via dma_resv_add_fence()
>> can outlive the hardware context (e.g. when a BO is exported as a
>> dma-buf and imported by another process). Using hwctx->name for the
>> fence
>> timeline name risks a use-after-free once the hwctx is destroyed.
>> Switch timeline name to dev_name() which is backed by the device that
>> outlives any individual context.
>>
>> Additionally, allocate a unique fence context via
>> dma_fence_context_alloc(1) for each job fence so that
>> dma_resv_add_fence()
>> does not evict a prior in-flight job's fence from a shared BO's
>> reservation object when multiple jobs touch the same BO. Also guard
>> hwctx_fini call in amdxdna_hwctx_destroy_rcu() against NULL ops.
>
> Is this aie4 kernel submission specific? aie2 does not publish this
> fence.
>
> If it does not fix any existing issue, please describe it clearly.
I have addressed your comments with a newer PATCH V1. This change is
merged with KMQ patches.
It is AIE4 specific.
>
>>
>> The corresponding AIE4 command submission BO locking and fence
>> attachment logic is implemented in a subsequent patch ("accel/amdxdna:
>> Implement AIE4 command packet building and submission").
>>
>> Co-developed-by: Max Zhen <max.zhen@amd.com>
>> Signed-off-by: Max Zhen <max.zhen@amd.com>
>> Signed-off-by: David Zhang <yidong.zhang@amd.com>
>> ---
>> drivers/accel/amdxdna/amdxdna_ctx.c | 29 ++++++++++++++++++++++-------
>> 1 file changed, 22 insertions(+), 7 deletions(-)
>>
>> diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c
>> b/drivers/accel/amdxdna/amdxdna_ctx.c
>> index 888e857ec558..6ca7774150d5 100644
>> --- a/drivers/accel/amdxdna/amdxdna_ctx.c
>> +++ b/drivers/accel/amdxdna/amdxdna_ctx.c
>> @@ -25,7 +25,7 @@
>> struct amdxdna_fence {
>> struct dma_fence base;
>> spinlock_t lock; /* for base */
>> - struct amdxdna_hwctx *hwctx;
>> + struct device *dev;
>> };
>> static const char *amdxdna_fence_get_driver_name(struct dma_fence
>> *fence)
>> @@ -39,7 +39,14 @@ static const char
>> *amdxdna_fence_get_timeline_name(struct dma_fence *fence)
>> xdna_fence = container_of(fence, struct amdxdna_fence, base);
>> - return xdna_fence->hwctx->name;
>> + /*
>> + * Use device name rather than hwctx name: the fence is
>> published into
>> + * BO reservation objects via dma_resv_add_fence() and can
>> outlive the
>> + * hwctx (e.g. when a BO is exported as a dma-buf and imported by
>> + * another process). The device outlives any individual context, so
>> + * dev_name() is safe to call at any point during the fence's
>> lifetime.
>> + */
>> + return dev_name(xdna_fence->dev);
>> }
>> static const struct dma_fence_ops fence_ops = {
>> @@ -55,9 +62,17 @@ static struct dma_fence
>> *amdxdna_fence_create(struct amdxdna_hwctx *hwctx)
>> if (!fence)
>> return NULL;
>> - fence->hwctx = hwctx;
>> + fence->dev = hwctx->client->xdna->ddev.dev;
>> spin_lock_init(&fence->lock);
>> - dma_fence_init(&fence->base, &fence_ops, &fence->lock,
>> hwctx->id, 0);
>> + /*
>> + * Part of the fix to align BO reservation locking and fence
>> + * management with AIE2: each job fence needs a unique context so
>> + * dma_resv_add_fence() does not evict a prior job's fence from a
>> + * shared BO's reservation object when two in-flight jobs touch
>> + * the same BO. The corresponding AIE4 command submission locking
>> + * and fence attachment is implemented in aie4_cmd_submit().
>> + */
>> + dma_fence_init(&fence->base, &fence_ops, &fence->lock,
>> dma_fence_context_alloc(1), 0);
>> return &fence->base;
>> }
>> @@ -81,13 +96,13 @@ static void
>> amdxdna_hwctx_release_expanded_heap(struct amdxdna_hwctx *hwctx)
>> static void amdxdna_hwctx_destroy_rcu(struct amdxdna_hwctx *hwctx,
>> struct srcu_struct *ss)
>> {
>> - struct amdxdna_client *client = hwctx->client;
>> - struct amdxdna_dev *xdna = client->xdna;
>> + struct amdxdna_dev *xdna = hwctx->client->xdna;
>> synchronize_srcu(ss);
>> /* At this point, user is not able to submit new commands */
>> - xdna->dev_info->ops->hwctx_fini(hwctx);
>> + if (xdna->dev_info->ops->hwctx_fini)
>> + xdna->dev_info->ops->hwctx_fini(hwctx);
>
> This seems unrelated. Please remove from the patch.
Removed.
David
>
> Lizhi
>
>> amdxdna_hwctx_release_expanded_heap(hwctx);
>> kfree(hwctx->name);
next prev parent reply other threads:[~2026-09-30 0:20 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 1:34 [PATCH V0 00/21] accel/amdxdna: Kernel submission and PM for AIE4 David Zhang
2026-09-26 1:34 ` [PATCH V0 01/21] accel/amdxdna: Rename NPU3 firmware files David Zhang
2026-09-26 1:34 ` [PATCH V0 02/21] accel/amdxdna: Remove mmap for doorbell David Zhang
2026-09-26 1:34 ` [PATCH V0 03/21] accel/amdxdna: Add CERT firmware version support David Zhang
2026-09-26 1:34 ` [PATCH V0 04/21] accel/amdxdna: Upgrade firmware version to 6.0 David Zhang
2026-09-28 17:08 ` Lizhi Hou
2026-09-26 1:34 ` [PATCH V0 05/21] accel/amdxdna: Add NPU3 classic device support David Zhang
2026-09-26 1:34 ` [PATCH V0 06/21] accel/amdxdna: Add AIE version query to aie4_get_info David Zhang
2026-09-26 1:34 ` [PATCH V0 07/21] accel/amdxdna: Add get and set power_mode for AIE4 David Zhang
2026-09-28 18:39 ` Lizhi Hou
2026-09-26 1:34 ` [PATCH V0 08/21] accel/amdxdna: Restore power mode override on AIE4 hardware start David Zhang
2026-09-28 18:48 ` Lizhi Hou
2026-09-26 1:34 ` [PATCH V0 09/21] accel/amdxdna: Add clock, DPM frequency, and resource info queries for AIE4 David Zhang
2026-09-26 1:34 ` [PATCH V0 10/21] accel/amdxdna: Add context switch hysteresis with debugfs control David Zhang
2026-09-26 1:34 ` [PATCH V0 11/21] accel/amdxdna: Refactor AIE4 hardware initialization sequence David Zhang
2026-09-26 1:34 ` [PATCH V0 12/21] accel/amdxdna: Decouple AIE4 doorbell and MSI-X notification transport hooks David Zhang
2026-09-28 20:16 ` Lizhi Hou
2026-09-26 1:34 ` [PATCH V0 13/21] accel/amdxdna: Implement AIE4 kernel queue lifecycle and memory layout David Zhang
2026-09-26 1:34 ` [PATCH V0 14/21] accel/amdxdna: Fix fence timeline name and context allocation David Zhang
2026-09-28 21:06 ` Lizhi Hou
2026-09-30 0:20 ` Zhang, Yidong (David) [this message]
2026-09-26 1:34 ` [PATCH V0 15/21] accel/amdxdna: Prepare for AIE4 command submission David Zhang
2026-09-26 1:34 ` [PATCH V0 16/21] accel/amdxdna: Implement AIE4 command packet building and submission David Zhang
2026-09-26 1:34 ` [PATCH V0 17/21] accel/amdxdna: Finalize runtime PM before acquiring dev_lock on removal David Zhang
2026-09-26 1:34 ` [PATCH V0 18/21] accel/amdxdna: Implement AIE4 suspend and resume David Zhang
2026-09-26 1:34 ` [PATCH V0 19/21] accel/amdxdna: Link SR-IOV VFs for power management sequencing David Zhang
2026-09-26 1:34 ` [PATCH V0 20/21] accel/amdxdna: Implement runtime suspend and resume support David Zhang
2026-09-26 1:34 ` [PATCH V0 21/21] accel/amdxdna: Add stub hwctx_config for AIE4 David Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=906d1899-26af-4829-8a4b-9d451ff13917@amd.com \
--to=yidong.zhang@amd.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=karol.wachowski@linux.intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=lizhi.hou@amd.com \
--cc=mario.limonciello@amd.com \
--cc=max.zhen@amd.com \
--cc=ogabbay@kernel.org \
--cc=quic_jhugo@quicinc.com \
--cc=sonal.santan@amd.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®